We need to blind the vectors aL, aR to make the proof zero knowledge.
The Prover creates randomly vectors sL and sR. On creating these, the
Prover can send commitments to these vectors;
these are properly blinded vector Pedersen commitments: